Etisalat IP Ranges
Etisalat is a UAE carrier licensed and regulated by the TDRA, and AS5384 is the number its domestic subscribers appear from. RIPE holds the record as EMIRATES-INTERNET under the organisation object ORG-ETC1-RIPE, with a description that still reads Emirates Internet, Public Internet Service, and a Dubai post box, and an aut-num last edited in November 2017. The blocks behind it carry the operator's older EMIRNET brand in their netnames: 86.96.0.0/14 was created on 20 April 2005 as AE-EMIRNET-20050420.
- Provider
- Etisalat
- Primary ASN
- AS5384
- Category
- ISP
- Headquarters
- Abu Dhabi, United Arab Emirates
- Announced IPv4 prefixes
- 2388
- Registry
- RIPE
Known IP ranges
These prefixes are currently announced to the global routing table by AS5384 (EMIRATES-INTERNET EMIRATES TELECOMMUNICATIONS GROUP COMPANY (ETISALAT GROUP) PJSC). Prefix sets change over time - use WHOIS Lookup for the authoritative record on any specific address.
86.96.0.0/14
94.56.0.0/14
2.48.0.0/14
92.96.0.0/14
31.218.0.0/15
94.56.0.0/15
94.58.0.0/15
217.164.0.0/15
176.204.0.0/15
83.110.0.0/15
2001:8f8:1f06::/48
2001:8f8:1f2e::/48 (IPv6)
What does an Etisalat IP mean in a privacy test?
An address on AS5384 puts the session inside Etisalat's UAE domestic network, and two things follow from that. The first is regulatory: under the TDRA's Internet Access Management policy the authority issues blocking and unblocking authorisations to its licensees, and the prohibited categories live in the policy's Annex 1, so the filtering happens inside the operator and a page that loads elsewhere can return a block notice on this address with nothing wrong at the connection level. The second is structural, and it is what a lookup usually gets wrong. RIPEstat's neighbour data gives AS5384 exactly one upstream, AS8966, the group's international and wholesale arm, against thirty-four downstreams of its own. Under the group's IPv6 allocation 2001:8f8::/29 the route6 objects name AS8966 dozens of times over against a bare handful for AS5384, so an Etisalat IPv6 address is usually not on this ASN at all. A UAE address that resolves to AS8966 is on the transit side rather than on a subscriber line.
What the registry holds for AS5384
Etisalat publishes no geofeed on the allocations behind this ASN and no customer-facing allowlist, so everything machine-readable comes from RIPE. The allocations sit under ORG-ETC1-RIPE, are maintained by ETISALAT-MNT, and use netnames of the form AE-EMIRNET followed by an eight-digit date. On the IPv4 side that date is the record's own creation date, so AE-EMIRNET-20050420 was created on 2005-04-20 and the netname saves you a query. On the IPv6 side it is not, and that catches people out: the allocation 2001:8f8::/29 is named AE-EMIRNET-20020920 but the RIPE object was created on 2013-07-17. Read the date in a netname as a label, not as a timestamp you can rely on.
The route objects carry more than the policy does, because the aut-num is thin for a network this size, naming only AS6453, AS3561 and AS4004. Those route objects are also where the group's internal boundary shows. Many on UAE-registered space are described as e& UAE via EMIX under origin 5384 and origin 8966 alike, and 86.96.120.0/24 carries the descr Roshan Afganistan via EMIX, spelling and all, with origin AS45178 and ETISALAT-MNT as its maintainer: Etisalat's own maintainer registering an Afghan operator's route on Emirati space, because EMIX carries other networks in and out of the region. What the registry does not carry is any location finer than the country. There is no emirate, no city and no per-prefix feed, so a city attached to an Etisalat address by a lookup service is that service's own estimate.
Subscriber, business circuit, or the transit side
Etisalat's own business documentation is unusually blunt about addressing on its Mobile Business Data Service: only private IP addressing is supported, dynamic or static, and the operator adds that it reserves a range of addresses for each subscription according to the number of users. Read the word static there carefully, because it is the trap: a static address on that product is a static private address sitting behind the carrier's translation, not a routable one, so a customer who was sold static IPs may still share a public address with everyone else on the pool. The practical consequence is that an inbound connection aimed at an AS5384 address is unlikely to reach a handset or a mobile router at all, and a repeated AS5384 address is weak evidence of the same device.
The second separation is between the group's own networks. AS5384 is the access side and RIPEstat shows it with a single upstream, AS8966, which is held by the same group under the holder string Etisalat-AS and operates the international and wholesale side; a UAE address that resolves to AS8966 is carrying somebody's transit rather than a subscriber's session. The same allocation also carries route objects under other origins, AS45178 among them, so the ASN a lookup reports for a prefix can differ from the one that holds the block around it. Confirm against the origin on the specific route object rather than the covering allocation before deciding which side of Etisalat you are looking at.
Related tools
Frequently asked questions
What IP ranges does Etisalat use in the UAE?
They are announced under AS5384, which RIPE holds with the as-name EMIRATES-INTERNET under ORG-ETC1-RIPE. The allocations are maintained by ETISALAT-MNT under netnames of the form AE-EMIRNET followed by a date, so 86.96.0.0/14 was created on 20 April 2005 as AE-EMIRNET-20050420. International and wholesale routes sit under AS8966 instead.
Why does my privacy test show an Etisalat IP?
An address on AS5384 puts the session inside Etisalat's UAE domestic network, and two things follow from that. The first is regulatory: under the TDRA's Internet Access Management policy the authority issues blocking and unblocking authorisations to its licensees, and the prohibited categories live in the policy's Annex 1, so the filtering happens inside the operator and a page that loads elsewhere can return a block notice on this address with nothing wrong at the connection level. The second is structural, and it is what a lookup usually gets wrong. RIPEstat's neighbour data gives AS5384 exactly one upstream, AS8966, the group's international and wholesale arm, against thirty-four downstreams of its own. Under the group's IPv6 allocation 2001:8f8::/29 the route6 objects name AS8966 dozens of times over against a bare handful for AS5384, so an Etisalat IPv6 address is usually not on this ASN at all. A UAE address that resolves to AS8966 is on the transit side rather than on a subscriber line.
Does Etisalat use carrier-grade NAT?
Its own business documentation states that the Mobile Business Data Service supports only private IP addressing, dynamic or static, and that a range is reserved per subscription according to the number of users. The device therefore holds a private address while the public one a remote server sees belongs to the carrier, and static on that product means a static private address rather than a routable one.
Is AS5384 the same network as AS8966?
No. AS5384 is the domestic access network and RIPEstat shows AS8966 as its only upstream. AS8966 is the group's international and wholesale side and is tied to the EMIX exchange. Under the group's IPv6 allocation 2001:8f8::/29 the route6 objects name AS8966 dozens of times over against a bare handful for AS5384.
Why are some sites blocked from an Etisalat address?
The TDRA operates an Internet Access Management policy under which the authority issues blocking and unblocking authorisations to its licensees, with the prohibited categories set out in the policy's Annex 1. The filtering happens inside the network rather than at the site, so a page that loads elsewhere can return a block notice on an AS5384 address with nothing wrong with the connection.